Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-20'

View all threats tagged with 'cwe-20'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-20

Threats Tagged 'cwe-20'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-54217: CWE-20 Improper input validation in Tobit Laboratories AG TeamDavidCVE-2026-54217
0

Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send an email containing malicious JavaScript code. When a user accesses the email, the stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524.

Join the discussion
CVE-2026-54208: CWE-20 Improper input validation in Tobit Laboratories AG TeamDavidCVE-2026-54208
0

Tobit Laboratories AG TeamDavid's Webbox application has a vulnerability that allows unauthenticated attackers to write arbitrary files on the server. This occurs due to improper input validation, enabling attackers to create or overwrite files with malicious content such as JavaScript. This can lead to stored cross-site scripting (XSS) when users access these files. The issue affects TeamDavid through Rollout 524. No patch or official remediation guidance is currently provided.

Join the discussion
CVE-2026-54207: CWE-20 Improper input validation in Tobit Laboratories AG TeamDavidCVE-2026-54207
0

CVE-2026-54207 is a medium severity vulnerability in Tobit Laboratories AG TeamDavid's Webbox component. The move archive functionality accepts arbitrary paths, including UNC network paths, without proper validation. This allows unauthenticated attackers to cause the server to initiate outbound SMB connections to attacker-controlled servers, potentially exposing NTLM authentication data. Exploitation can lead to SMB relay or credential theft attacks if outbound SMB connections are allowed. The issue affects TeamDavid through Rollout 524. No patch or official remediation is currently confirmed.

Join the discussion
CVE-2026-54206: CWE-20 Improper input validation in Tobit Laboratories AG TeamDavidCVE-2026-54206
0

CVE-2026-54206 is a medium-severity vulnerability in Tobit Laboratories AG TeamDavid's Webbox component. The vulnerability arises from improper input validation of the @@INCLUDE command, which accepts UNC network paths without validation. This causes the server to make outbound SMB connection attempts to attacker-controlled servers, potentially exposing NTLM authentication information. Exploitation of the pathname parameter is possible without authentication. This issue affects TeamDavid through Rollout 524. No official patch or remediation guidance is currently available.

Join the discussion
CVE-2026-54205: CWE-20 Improper input validation in Tobit Laboratories AG TeamDavidCVE-2026-54205
0

Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB servers. This enables authenticated attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information (such as NTLM hashes). If outbound connections to port 445 (SMB) are permitted, attackers can use this to conduct SMB relay or credential theft attacks. Exploitation of the “pathname” parameter is possible without authentication. This issue affects TeamDavid through Rollout 524.

Join the discussion
CVE-2026-54204: CWE-20 Improper input validation in Tobit Laboratories AG TeamDavidCVE-2026-54204
0

CVE-2026-54204 is a high-severity vulnerability in Tobit Laboratories AG TeamDavid's Webbox search functionality. The 'pathnameroot' parameter accepts UNC paths without validation, allowing unauthenticated attackers to cause the server to connect to attacker-controlled SMB servers. This can lead to exposure of NTLM authentication information and enable SMB relay or credential theft attacks if outbound SMB connections are allowed. The issue affects TeamDavid through Rollout 524. No official patch or remediation guidance is currently available.

Join the discussion
CVE-2026-54199: CWE-20 Improper input validation in Tobit Laboratories AG TeamDavidCVE-2026-54199
0

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection via improper input validation in the link storing functionality. The vulnerability arises because user input from the request body is appended to the redirect target in a 302 HTTP response without sufficient sanitization. Injection of a line feed character allows an attacker to manipulate HTTP response headers. This issue affects TeamDavid through Rollout 524. No patch or official remediation guidance is currently available.

Join the discussion
CVE-2026-15149: CWE-20 Improper Input Validation in WP Hotel BookingCVE-2026-15149
0

A vulnerability in the WP Hotel Booking WordPress plugin before version 2.3.3 allows unauthenticated users to manipulate room quantities and order totals when placing bookings. This improper input validation enables attackers to create confirmed reservations for free or at a reduced price by exploiting client-controlled cart data.

Join the discussion
CVE-2026-14225: CWE-20 Improper Input Validation in Easy AppointmentsCVE-2026-14225
0

Easy Appointments WordPress plugin versions through 3.12.26 contain an input validation vulnerability in shortcode processing. The plugin only validates the first tag of a shortcode string against an allowlist but renders the entire string, allowing users with contributor-level access to execute arbitrary registered shortcodes. The vulnerability has a low CVSS score of 2.7 and does not appear to have known exploits in the wild.

Join the discussion
CVE-2024-6541: CWE-20: Improper Input Validation in WSO2 WSO2 Micro IntegratorCVE-2024-6541
0

The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive information belonging to other users or the unintended modification of system data by authenticated users. The exact impact depends on how `messageContext` properties are utilized within the affected WSO2 products.

Join the discussion

Showing 1 to 10 of 120 results

Filters:Tag: cwe-20
Page 1 of 12
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses